Back in 09 there was a buzz about token kidnapping by Argeniss
http://www.argeniss.com/research.html
http://www.argeniss.com/research/TokenKidnapping.pdf
subsequently patched http://www.microsoft.com/technet/security/bulletin/MS09-012.mspx
I'm normally violently against uploading binaries to boxes but until the local exploit functionality is added to msf...
The gist is you an run the Churrasco binary and it will execute a command for you as SYSTEM from NETWORK SERVICE (the shell privs you get when exploiting IIS). See the slides for more.
Lets see it in action.
